The telnet parser in tcpdump before 4.9.2 has a buffer over-read in print-telnet.c:telnet_parse().
{ "vanir_signatures": [ { "id": "CVE-2017-12988-29bcf351", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/8934a7d6307267d301182f19ed162563717e29e3", "deprecated": false, "signature_version": "v1", "signature_type": "Function", "digest": { "length": 2231.0, "function_hash": "3174917664439056968835398981928661099" }, "target": { "file": "print-telnet.c", "function": "telnet_parse" } }, { "id": "CVE-2017-12988-3fffa537", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/8934a7d6307267d301182f19ed162563717e29e3", "deprecated": false, "signature_version": "v1", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "287370690541610701360793441734267325906", "57100495640581646232050786450472498004", "147460875534616350229031090682247365674", "224198201307392529602952091072839023317" ] }, "target": { "file": "print-telnet.c" } } ] }